The article examines modern approaches to automating the process of testing web applications for penetration. The growing number and complexity of web threats, as well as limited resources for manual testing, create a critical need for the effective use of automated testing tools. However, the diversity of architectures, operating principles, and functional capabilities of existing pentesting tools creates a problem of informed choice and effective combination. The purpose of the article is to systematise the main open source tools and conduct a comparative analysis based on a set of developed criteria. The paper proposes classifying tools into four categories: proxy-based active scanners (e.g., OWASP ZAP), template-based scanners (Nuclei), specialised exploitation tools (sqlmap), and fuzzers/parameter scanners (ffuf). For comparative analysis, a system of criteria was defined, including functional (OWASP Top-10 coverage, support for modern technologies), operational (integration into CI/CD, usability) and technical (licence, development activity) aspects. Based on these criteria, the tools representing each category were analysed. The results of the study showed that no tool is un
📖 افتح في inklap 🔗 DOI 📮 اطلب بحثاً